Impact
Adobe Campaign Classic is impacted by an Improper Input Validation flaw that can lead to arbitrary code execution in the context of the current user. The vulnerability allows a low‑privileged attacker to remotely execute code without any user interaction. The exploit requires conditions beyond the attacker’s control, but when those conditions are met the attacker gains full control of the application instance and can further compromise the underlying system. This represents a high‑risk integrity breach and a complete loss of data protection for affected deployments.
Affected Systems
The affected product is Adobe Campaign Classic from Adobe. No specific version numbers are provided in the advisory, so any instance that matches the vendor and product name should be verified against Adobe’s official patch status.
Risk and Exploitability
The CVSS score of 8.5 categorises the flaw as High severity. The EPSS score is not available, indicating either no aggregated exploitation data or insufficient data points; the actual likelihood of exploitation is therefore uncertain. The vulnerability is not listed in the CISA KEV catalog, reducing immediate knowledge of being actively exploited. Nonetheless, the lack of user interaction and the potential breadth of damage make it a top‑priority risk, especially if the required external conditions can be satisfied by an attacker.
OpenCVE Enrichment